Infosec News Nuggets — July 23, 2026
Brief
Check Point Warns of SmartConsole Zero-Day Exploited in Attacks
Check Point patched CVE-2026-16232, an authentication bypass vulnerability in its SmartConsole GUI admin panel that allows unauthenticated attackers to obtain an application login token usable to authenticate with administrator privileges on a vulnerable Security Management Server.
Successful exploitation requires the Management Server IP to be exposed to internet access with no restrictions on Trusted Clients, after which an attacker can modify security policies and configurations across the affected deployment; Check Point says the flaw has affected “a very small number of customers” so far.
